Trojan

How to remove “Trojan:Win32/Ekstak.ASDY!MTB”?

Malware Removal

The Trojan:Win32/Ekstak.ASDY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ekstak.ASDY!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Ekstak.ASDY!MTB?


File Info:

name: 56858DD5BE3765FE9A81.mlw
path: /opt/CAPEv2/storage/binaries/1d650cf9abb5c59d4ad8a0305cd5a7e30b3531406b8542208b3f51b9a642118e
crc32: D9E97A0E
md5: 56858dd5be3765fe9a81077924c9facf
sha1: 9d130008f049dfc1ccef8d21ec7dc6c3c8b79f51
sha256: 1d650cf9abb5c59d4ad8a0305cd5a7e30b3531406b8542208b3f51b9a642118e
sha512: 229689a627d678533c97dabb424a94ff26027c962808392d9c3702cbf4e958cf2d2f703c228e733b62628fae970b353b3b699191f6cc871a8b6e61300cbfb9e0
ssdeep: 196608:4cHD7cxwOrgk86z57itvanaUmLPvJ6LuoFgdiF:P7Gw28+itvmapLPvMLu4gdI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155663325649B8033F357CC396C56D05EDDDA7A282DD092403AF8097F8A773AE620A7F5
sha3_384: eb4a71a0dede9f8452ffb4f4e0384c41288b9a3b350cf62b69d27d54ac031d42309957323174fdb82d12da0fbdefc83a
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-12-22 05:58:52

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: FlatControlSTD Setup
FileVersion:
LegalCopyright:
ProductName: FlatControlSTD
ProductVersion: 1.2.2.2
Translation: 0x0000 0x04b0

Trojan:Win32/Ekstak.ASDY!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.ObfuscatedPoly.vc
McAfeeArtemis!56858DD5BE37
Cylanceunsafe
ZillyaTrojan.Ekstak.Win32.76331
SangforDropper.Win32.Ekstak.Vol8
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.Win32.Ekstak.askhi
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Ymhl
F-SecureTrojan.TR/Drop.Agent.zxtim
DrWebTrojan.Siggen22.48026
TrendMicroTROJ_GEN.R002C0DLS23
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
JiangminTrojan.Ekstak.cils
VaristW32/Agent.BIZR-5116
AviraTR/Drop.Agent.zxtim
MicrosoftTrojan:Win32/Ekstak.ASDY!MTB
ZoneAlarmTrojan.Win32.Ekstak.askhi
GDataWin32.Trojan.Agent.BM0VR1
AhnLab-V3Trojan/Win.Malware-gen.R628635
MalwarebytesTrojan.Dropper
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLS23
MaxSecureTrojan.Malware.221766767.susgen
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Ekstak.ASDY!MTB?

Trojan:Win32/Ekstak.ASDY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment